Skip to content

v1.10.0 — HPOS fraud statuses, REST credential check, rolling decline window

Choose a tag to compare

@rafael-minuesa rafael-minuesa released this 05 Sep 12:43
· 10 commits to main since this release

First release assembled from reviewed Codex pull requests (#2, #3, #4, #5, #6, #8).

Fixed

  • Fraud orders were invisible on the HPOS Orders list. Statuses are now registered and stored as wc-fraud-auto and wc-fraud-stripe, like WooCommerce's own. A one-time migration on the first request after updating rewrites the old values in wp_posts and the HPOS tables, backfills the persistent fraud flag, and clears caches, with direct SQL so no status hooks, notes, or emails fire. The combined Fraud view now exists on HPOS too, the Activity Log and Reports read the authoritative store, refunded fraud orders count in Reports, and alert emails use the HPOS-aware edit link. Usage-report counter key moves from marked:fraud-auto-cancelled to marked:fraud-auto. (#5)
  • REST hardening no longer trusts credential-like input. Only a request WooCommerce authenticated as a manage_woocommerce user, or one with a valid Store API nonce, passes. WooCommerce's own permission check already refused fake credentials, so this hardens the plugin's layer. (#3)
  • Repeated payment failures are counted over a true rolling 24 hours. Existing clusters keep their count for one more window. (#4)
  • IP repeat tracking no longer grows without bound. One expiring transient per IP; the old wcaf_ip_store option is removed on first use. (#6)
  • Post-payment rules never fall back to the request IP. (#6)
  • wcaf_suspicious_order_detected always receives three arguments. (#8)

Changed

  • Every outbound request sends a WC-Antifraud/<version> WordPress/<version> User-Agent instead of WordPress's default, which carries the site URL. README privacy section reworded. (#2)

Full details in CHANGELOG.md.